RansomLook 的遗留数据库导出功能存在授权漏洞,可能导致未认证远程用户检索本应保密的信息。 端点允许导出某些内部数据库,且无需进行身份认证。尽管部分实体数据库在导出时会执行有限的过滤处理,但其他可导出数据库则直接返回,未能一致地应用应用对私有实体的访问限制。因此,与组、市场、帖子或其他标记为“私有”的记录相关联的信息,可能会被包含在未认证请求者可访问的导出文件中。 能够访问 RansomLook Web 应用的攻击者可以请求受影响的导出端点,并检索仅授权用户才能访问的数据。根据具体实例的内容,这可能会泄露私
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ransomlook | ransomlook | 0 ~ 2.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-78387 | 9.4 CRITICAL | RansomLook Missing Authorization in Web Configuration Editor Allows Application Configurat |
| CVE-2026-78555 | 9.4 CRITICAL | RansomLook API Key Disclosure Through /admin/apikeys HTML Source |
| CVE-2026-78372 | 9.2 CRITICAL | RansomLook Missing Authorization Allows Disclosure of Private Group and Ransom Note Data |
| CVE-2026-78369 | 8.8 HIGH | Missing Authentication Allows Unauthorized Creation of Crypto Groups in RansomLook |
| CVE-2026-78391 | 8.8 HIGH | Stored Cross-Site Scripting via Untrusted Cryptocurrency Address Rendering in RansomLook |
| CVE-2026-78551 | 8.8 HIGH | RansomLook Login Endpoint Allows Timing-Based Username Enumeration and Unthrottled Authent |
| CVE-2026-78380 | 8.7 HIGH | Private Group and Market Posts Disclosed Through Public Notification Channels in RansomLoo |
| CVE-2026-78386 | 8.7 HIGH | Unauthenticated Disclosure of Scraping Credentials and Bypass Configuration via RansomLook |
| CVE-2026-78381 | 8.2 HIGH | RansomLook Arbitrary File Read via Path Traversal in Post screen Field |
| CVE-2026-78385 | 8.2 HIGH | RansomLook Analysis PDF Generation Allows Server-Side Request Forgery and Arbitrary Local |
| CVE-2026-78553 | 7.0 HIGH | Insecure Flask Secret-Key File Permissions Allow Local Administrator Session Forgery in Ra |
| CVE-2026-78378 | 6.9 MEDIUM | Redis Glob Pattern Injection Allows Unauthorized Enumeration of Private Ransomlook Data |
No comments yet